2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-29875 | CRITICAL | 9.8 | 0.9% | Mar 21, 2024 | SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/default/reports/exportactiveuserrpt, 'sort... |
| CVE-2024-29874 | CRITICAL | 9.8 | 0.9% | Mar 21, 2024 | SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/default/reports/activeuserrptpdf, 'sort_nam... |
| CVE-2024-29873 | CRITICAL | 9.8 | 0.8% | Mar 21, 2024 | SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/reports/businessunits/format/html, 'bunitna... |
| CVE-2024-29872 | CRITICAL | 9.8 | 0.8% | Mar 21, 2024 | SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/empscreening/add, 'agencyids' parameter. Th... |
| CVE-2024-29871 | CRITICAL | 9.8 | 0.9% | Mar 21, 2024 | SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/sentrifugo/index.php/i... |
| CVE-2024-29870 | CRITICAL | 9.8 | 0.9% | Mar 21, 2024 | SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/format/html, 'business... |
| CVE-2024-29866 | CRITICAL | 9.1 | 0.7% | Mar 21, 2024 | Datalust Seq before 2023.4.11151 and 2024 before 2024.1.11146 has Incorrect Access Control because a Project Owner or Or... |
| CVE-2024-29732 | CRITICAL | 9.8 | 0.5% | Mar 21, 2024 | A SQL Injection has been found on SCAN_VISIO eDocument Suite Web Viewer of Abast. This vulnerability allows an unauthent... |
| CVE-2024-27438 | CRITICAL | 9.8 | 1.0% | Mar 21, 2024 | Download of Code Without Integrity Check vulnerability in Apache Doris. The jdbc driver files used for JDBC catalog is n... |
| CVE-2024-1148 | CRITICAL | 9.8 | 0.7% | Mar 21, 2024 | Weak access control in OpenText PVCS Version Manager allows potential bypassing of authentication and uploading of files... |
| CVE-2024-1147 | CRITICAL | 9.8 | 0.7% | Mar 21, 2024 | Weak access control in OpenText PVCS Version Manager allows potential bypassing of authentication and download of files. |
| CVE-2024-2161 | CRITICAL | 9.8 | 0.9% | Mar 21, 2024 | Use of Hard-coded Credentials in Kiloview NDI allows un-authenticated users to bypass authenticationThis issue affects K... |
| CVE-2024-29864 | CRITICAL | 9.8 | 2.9% | Mar 21, 2024 | Distrobox before 1.7.0.1 allows attackers to execute arbitrary code via command injection into exported executables. |
| CVE-2024-29859 | CRITICAL | 9.8 | 0.8% | Mar 21, 2024 | In MISP before 2.4.187, add_misp_export in app/Controller/EventsController.php does not properly check for a valid file ... |
| CVE-2024-29858 | CRITICAL | 9.8 | 0.4% | Mar 21, 2024 | In MISP before 2.4.187, __uploadLogo in app/Controller/OrganisationsController.php does not properly check for a valid l... |
| CVE-2024-2054 | CRITICAL | 9.8 | 81.3% | Mar 21, 2024 | The Artica-Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users... |
| CVE-2024-2014 | CRITICAL | 9.8 | 1.1% | Mar 21, 2024 | A vulnerability classified as critical was found in Panabit Panalog 202103080942. This vulnerability affects unknown cod... |
| CVE-2024-28123 | CRITICAL | 9.8 | 0.8% | Mar 21, 2024 | Wasmi is an efficient and lightweight WebAssembly interpreter with a focus on constrained and embedded systems. In the W... |
| CVE-2024-27922 | CRITICAL | 9.8 | 0.8% | Mar 21, 2024 | TOMP Bare Server implements the TompHTTP bare server. A vulnerability in versions prior to 2.0.2 relates to insecure han... |
| CVE-2024-25239 | CRITICAL | 9.8 | 0.8% | Mar 21, 2024 | SQL Injection vulnerability in Sourcecodester Employee Management System v1.0 allows attackers to run arbitrary SQL comm... |
| CVE-2024-1202 | CRITICAL | 9.8 | 0.9% | Mar 21, 2024 | Authentication Bypass by Primary Weakness vulnerability in XPodas Octopod allows Authentication Bypass. This issue affe... |
| CVE-2024-29026 | CRITICAL | 9.1 | 0.4% | Mar 20, 2024 | Owncast is an open source, self-hosted, decentralized, single user live video streaming and chat server. In versions 0.1... |
| CVE-2024-29037 | CRITICAL | 9.1 | 0.6% | Mar 20, 2024 | datahub-helm provides the Kubernetes Helm charts for deploying Datahub and its dependencies on a Kubernetes cluster. Sta... |
| CVE-2024-29033 | CRITICAL | 9.1 | 0.6% | Mar 20, 2024 | OAuthenticator provides plugins for JupyterHub to use common OAuth providers, as well as base classes for writing one's ... |
| CVE-2024-25294 | CRITICAL | 9.1 | 1.0% | Mar 20, 2024 | An SSRF issue in REBUILD v.3.5 allows a remote attacker to obtain sensitive information and execute arbitrary code via t... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now